Vulnerability Description
Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code undetected by the operating system.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Amd Generic Encapsulated Software Architecture | - |
References
- https://www.amd.com/en/corporate/product-securityVendor Advisory
- https://www.amd.com/en/corporate/product-securityVendor Advisory
FAQ
What is CVE-2020-12890?
CVE-2020-12890 is a vulnerability with a CVSS score of 6.7 (MEDIUM). Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Enc...
How severe is CVE-2020-12890?
CVE-2020-12890 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12890?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Amd Generic Encapsulated Software Architecture.